Privacy policy.

Regulars · Aous Labs LLC · last updated 2026-09-02

01 · What we collect

Cardholders: your name and phone number at sign-up. Then every visit — the date, which counter phone served you, what it earned, and any reward you took; where a café awards points by item or by spend, that line also records the items or the value of the bill. Points go on when staff scan your card or you scan the café's code, and come off when you redeem.

Your wallet pass: a serial number, a token that authenticates it, an identifier for the device you added it to, that device's push token, and when you added it. These identify a pass on a device, not your movements.

The two wallet platforms are not the same. Google keeps your card on its own servers, so it holds your full name, our internal reference for you, and the café's shop addresses. Apple gets none of that — we build and sign the card ourselves and send it straight to your phone, so the file, your first name on it, lives only on your device. All Apple ever receives from us is an empty "this card changed" ping addressed to your phone. Neither gets your phone number.

Café owners: your business name and logo, your own name, the email we bill and write to, and your shop addresses. There is no field anywhere for an owner's phone number. Subscribing adds your Stripe customer and subscription references, your plan status, and your trial and grace dates — invoices stay at Stripe, and your card number never touches our servers. Staff get a counter-phone name and a scrambled PIN; the PIN itself is never stored. An enquiry you email us is not stored in the product at all. If you connect your Instagram to post announcements, we also hold the account id and @username you connected and the access token Instagram issues us for posting to it — the café's own grant, revocable from Instagram at any time — plus the photos or videos you attach to an announcement.

02 · What we use it for

Running the loyalty card: issuing your pass, updating stamps in real time, showing the café how its program performs, and keeping owner subscriptions running. Owner enquiries are used to reply to you — nothing else.

We never message cardholders ourselves. Two things can reach you, and both come from the café whose card you hold. It can send its cardholders a short note — at most one a day, 140 characters — which arrives on the card itself, the same way a stamp does. And if it has set up its shop addresses, your phone can bring the card up when you are near one: quietly on the lock screen on iPhone, and as a notification from Google Wallet on Android. That second one is your own phone acting on a shop address written on your card — we are never told where you are, and there is no field anywhere in our system that could hold a customer's location. Beyond those two there is nothing: we hold no email address for you, and nothing here sends a text message. Remove the card from your wallet and it all stops. A café may choose to publish the same announcement to its own Instagram; that is public on the café's own account, not on your card. And a café may have the note drafted for it by a machine from its own photo and its own words — the draft is always shown to the café and approved by them before anything is sent, and nothing about you is part of it.

We do not sell data. We do not run ads. This site sets no cookies, and its analytics is cookieless and never follows you across the web. The tools we and cafés sign in to — the staff scanner and our own admin — set one sign-in cookie, so staff are not asked for their PIN on every scan.

03 · Where it lives

Everything we hold runs on Railway in Amsterdam — application and database both in the Netherlands, inside the European Union. Images a café uploads — their logo, and any reference pictures they send us for custom stamp artwork — are stored on Cloudflare R2 in the European Union.

Who else touches it: Railway hosts all of it. Google holds the Google Wallet copy of a card, as described in 01. Apple receives only that empty ping. Stripe handles café payments. Resend sends our emails to café owners and never sees a cardholder. Cloudflare does two jobs: it stores those uploaded images, and its Turnstile check sits on our public forms to keep bots out — that check runs in the visitor's browser, so Cloudflare sees their IP address and how their browser behaves, and nothing else about them. OpenStreetMap answers a café's address search and draws the map it drops its pin on — that map loads in the owner's own browser, so OpenStreetMap sees their IP address. All of them process data where they operate, including the United States. Inside Regulars, access is limited to Aous Labs LLC operators. Two more, only when a café uses announcements: Microsoft — the café's own photo and their own words are sent to Azure OpenAI (Sweden Central, inside the European Union) to draft the caption and the note; Microsoft keeps what is sent for 30 days for abuse monitoring, and no cardholder data is ever sent — not a name, not a number, not a count, not a wallet identifier. Meta — receives the media and the caption the café chose to publish, which is then public on the café's own Instagram, and holds the access grant to that account.

04 · How long

Cardholder data is kept while the café's program runs. Ask the café to remove you and it can do that from its dashboard on the spot: your name, number and points are deleted, and the card in your wallet is retired — greyed out at Apple, closed at Google with your name taken off it. Or write to [email protected] and we will pass it on.

If a café leaves Regulars, we start deleting its cardholder records 30 days after the end of service — the same deletion, wallet cards included — and keep going daily until they are gone. Its dashboard stays reachable in the meantime, so it can export its list first.

Sign-in links and reward codes go once used or expired. After a card is closed we keep its pass serial, and nothing else about the person, for up to 90 days — that is what lets us tell their phone the card is dead if it has not checked in yet. The record of who opened a café's dashboard (see 05) is kept for 180 days. Your café's account and billing records are kept while your subscription runs and after it ends, for accounting and tax; ask us and we will delete what the law does not require us to keep.

One exception, in your favour: an account that goes 37 days without ever issuing a single card is deleted outright — the account, your name and your email with it — and the café name it was using goes back into circulation for someone else. If you signed up and never used it, we do not keep you.

05 · Security

Everything between your phone or browser and us travels over an encrypted connection. Inside our own infrastructure the application and its database talk on a private network that is not reachable from the internet. A café's dashboard is reached through a private link, so we record every time one is opened: the day, how many times, and a one-way code standing in for the visitor — never a name, an address, or anything about the cardholders on the list. The café can see that record itself, under Settings, and ask us for a fresh link if a visitor appears it does not recognise.

No system is perfect; if a breach ever affects you, we'll tell you and the relevant authorities as the law requires.

06 · Your rights and contact

Wherever you live — GDPR, CCPA, or anywhere else — the deal is the same. Your own card page shows what we hold about you. The café can delete you from its dashboard on the spot. Corrections we still make by hand, so ask the café to email [email protected] and we will change it. The service isn't directed at children: a loyalty card doesn't need a birthday and we never ask for one.

Controller for owner data, and processor for café programs: Aous Labs LLC, registered in Wyoming, United States. If this policy materially changes, the date above changes with it and subscribers are told.

Questions about this policy: [email protected].